CVE-2026-32596 is a high-severity authentication bypass vulnerability (CVSS 7.5) affecting Glances, an open-source system monitoring tool, in versions prior to 4.5.2. When the Glances web server is started with `glances -w`, it defaults to running without authentication, exposing its REST API to any network client. This allows unauthenticated remote attackers to access sensitive system information, including credentials (passwords, API keys, tokens) found in process command-lines. The attack vector is network-based with low complexity, leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though the vulnerability has received minimal community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.2CPE matchmatch criteria | cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.